typeanalysisfamilyquasarconfidencehighcreated2026-08-18updated2026-08-18dotnetratmalware-familyc2persistencecollectiondefense-evasiondiscoveryexecutionmitre-attck
SHA-256: 1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd

quasar: 1ba40977 — xClient.Core rebranded variant, v1.3.0.0, May 2026 build

Executive Summary — A near-stock build of a Quasar-derived open-source .NET RAT, compiled May 2026, with namespaces rebranded from Quasar.Client/Quasar.Common to xClient.Core. Unobfuscated .NET Framework 4.0 Client Profile PE32 (~348 KB). No packing, no obfuscation, no CAPE detonation possible. The OpenCTI 9d2ca3 label is a misattribution; this binary shares zero build artefacts with the MinGW/Go/.NET dropper cluster.

What It Is

  • File: 1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd.bin, 348 KB (356,352 bytes) ^[file.txt]
  • Format: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt]
  • Toolchain: .NET Framework 4.0 Client Profile / CLR v4.0.30319, linker v8.0, compiled Thu May 28 05:07:02 2026 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Assembly version: 1.3.0.0 ^[pefile.txt:233] ^[exiftool.json:27]
  • Version info: InternalName Client.exe, OriginalFilename Client.exe, FileVersion 1.3.0.0; all other fields (CompanyName, ProductName, LegalCopyright, FileDescription) are blank ^[exiftool.json:36-46]
  • Signed: No ^[rabin2-info.txt:27]
  • Packed / obfuscated: None. Entropy of .text section 6.45 (typical for unobfuscated CIL). ^[pefile.txt:92]
  • Dynamic analysis: Skipped — no CAPE Windows guest available. ^[dynamic-analysis.md]

Family attribution is high-confidence: the binary contains the literal namespace strings xClient.Core.MouseKeyHook, xClient.Core.ReverseProxy.Packets, xClient.Core.Recovery.Browsers, xClient.Core.Registry, xClient.Core.Compression, xClient.Core.NetSerializer, xClient.Core.Packets.ServerPackets, and xClient.Core.Packets.ClientPackets throughout the string table. ^[strings.txt:57] ^[strings.txt:166] ^[strings.txt:210] ^[strings.txt:556] ^[strings.txt:711] ^[strings.txt:975] ^[strings.txt:1070] ^[strings.txt:1282] ^[strings.txt:1567] ^[strings.txt:1617] These namespaces map one-to-one onto the Quasar RAT architecture (see quasar); xClient.Core is the historical predecessor namespace from the xRAT codebase that Quasar was forked from. The NetSerializer library (custom serialization, not protobuf-net) was the original transport layer in early Quasar/xRAT builds. ^[strings.txt:1617]

The OpenCTI 9d2ca3 tag assigned at triage is a false positive. The 9d2ca3 cluster is characterised by MinGW-w64 encrypted droppers, Go infostealers, and lightweight .NET stagers — none of which match this .NET Framework 4.0 full-featured RAT. ^[entities/9d2ca3.md]

How It Works

Quasar is a modular .NET RAT with a plugin-like command architecture. The client binary connects to a Quasar/xRAT server; the C2 host/port are configured at build time or injected post-build. Communication uses the custom NetSerializer binary protocol over TCP sockets. ^[strings.txt:1617] ^[capa.txt]

Key modules visible in unobfuscated CIL metadata:

  • Keylogging: Global hooks via xClient.Core.MouseKeyHook. Capa detects log keystrokes via polling (2 matches). ^[strings.txt:210] ^[capa.txt]
  • Credential harvesting: xClient.Core.Recovery.Browsers namespace + capa gather chrome based browser login information. ^[strings.txt:975] ^[capa.txt]
  • Remote shell: DoShellExecute / DoShellExecuteResponse message types. ^[strings.txt:1208] ^[strings.txt:1436]
  • File manager: Chunked file transfer via FileSplit + FileChunk (implied by MaxBlocks, CurrentBlock, Block packet fields). ^[strings.txt:1159]
  • Desktop / webcam capture: GetMonitors, MonitorIndex, DoWebcamStop, VideoCaptureDevice, AForge.Video.DirectShow. ^[strings.txt:1135] ^[strings.txt:2118] ^[strings.txt:2149]
  • Reverse proxy: ReverseProxyConnect, ReverseProxyDisconnect, ReverseProxyData. ^[strings.txt:166] ^[strings.txt:196] ^[strings.txt:200]
  • System information: GetSystemInfo, GetSystemInfoResponse, OS version query, network interface enumeration, drive listing, process enumeration, geo-location query. ^[strings.txt:1200] ^[strings.txt:1424] ^[capa.txt]
  • Registry manipulation: Full read/write/delete on HKCU/HKLM; RegistryEditor, RegistrySeeker, RegSeekerMatch. ^[strings.txt:711] ^[strings.txt:737] ^[strings.txt:763]
  • Persistence: DoStartupItemAdd, DoStartupItemRemove, and capa schedule task via schtasks (2 matches). ^[strings.txt:1150] ^[strings.txt:1207] ^[capa.txt]
  • Self-update / uninstall: DoClientUpdate, DoClientUninstall. ^[strings.txt:1232] ^[strings.txt:1278]
  • Cryptography: Capa reports DPAPI encryption, SHA1/SHA256 hashing, Base64 encode/decode, and AES via Rfc2898DeriveBytes + AesCryptoServiceProvider. ^[capa.txt] ^[strings.txt:1534] ^[strings.txt:1538]
  • Process injection / manipulation: CreateProcess, TerminateProcess, SuspendThread, VirtualAlloc equivalents via .NET Process / Thread APIs. ^[capa.txt]

No hardcoded C2 host, port, mutex, or password is visible in plaintext strings — the builder injects these at compile time or stores them in an encrypted config block not recoverable statically. Without runtime detonation, C2 IOCs are absent.

Decompiled Behavior

Not applicable. The binary is pure .NET CIL (not native x86 code) and Ghidra does not produce meaningful pseudo-C from CIL. The assembly is completely unobfuscated — behaviour is recoverable directly from static strings, capa, and pefile metadata without decompiler output. No control-flow obfuscation, no string encryption, no anti-debug checks, and no anti-VM logic were identified.

C2 Infrastructure

Not recoverable statically. The Quasar/xRAT builder injects C2 credentials at compile time; they are not stored as plaintext resources in this sample. No IP addresses, domains, URL patterns, or mutex names were found in the string table. ^[strings.txt] Without dynamic execution or access to builder output / campaign artefacts, C2 IOCs are absent.

Interesting Tidbits

  • Namespace rebrand evasion: The threat actor (or builder operator) changed Quasar.Client → xClient.Core and stripped the MaxXor copyright, but left every other artefact intact — AForge, MouseKeyHook, NetSerializer, and the full packet type enumeration. This is a superficial rebrand, not a fork. ^[strings.txt]
  • Version down-grade: Assembly version 1.3.0.0 is lower than the well-documented 1.4.1.0 builds in corpus siblings. This suggests either an older codebase or a deliberate version rollback to evade signature-based detection. ^[pefile.txt:233]
  • Blank version-info fields: Unlike stock Quasar builds that carry Quasar Client / Copyright © MaxXor, this sample blanks all human-readable fields except InternalName/OriginalFilename (Client.exe). ^[exiftool.json]
  • No evasion at all: No anti-VM, no anti-debug, no sandbox detection, no sleep loops, no WMI/CPUID checks. A stock open-source build dropped straight onto a victim. ^[capa.txt]
  • FLOSS failure: The flare-floss invocation failed with an argument-parsing error (--no flag collision with the sample path). ^[floss.txt] Decoded strings were unnecessary — the assembly is unobfuscated.
  • Recent build date: Compiled May 28 2026 — this is a actively maintained/build variant, not a stale 2014-era artefact. ^[pefile.txt:34]

How To Mess With It (Homelab Replication)

Goal: Build your own Quasar/xRAT client and compare its capa fingerprint to this sample.

  1. Clone the public repository: git clone https://github.com/quasar/Quasar.git (or the historical xRAT fork).
  2. Open Quasar.sln in Visual Studio 2019/2022.
  3. In the Client project, rename namespaces from Quasar.Client / Quasar.Common to xClient.Core to match this rebrand.
  4. Build the Client project in Release mode targeting .NET Framework 4.0 Client Profile.
  5. The output Client.exe will carry the same capa namespace hits: compiled to the .NET platform, create TCP socket, send data, receive data, encode data using Base64, hash data using SHA1, log keystrokes via polling, query or enumerate registry key, create process in .NET, etc.
  6. Verification: Run capa Client.exe. The capability table should closely match this sample's capa.txt — expect ~60+ host-interaction hits, ~10 communication hits, and the same ATT&CK tactic coverage.
  7. Learning outcome: You will see exactly how a namespace-rebranded .NET RAT looks in strings and capa — useful baseline for spotting superficial evasion attempts.

Deployable Signatures

YARA rule

rule quasar_xclient_rebrand
{
    meta:
        description = "Quasar/xRAT variant rebranded with xClient.Core namespace — v1.3.x build fingerprint"
        author = "Titus"
        date = "2026-08-18"
        sha256 = "1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd"
    strings:
        $ns1 = "xClient.Core.MouseKeyHook" ascii wide
        $ns2 = "xClient.Core.ReverseProxy.Packets" ascii wide
        $ns3 = "xClient.Core.Recovery.Browsers" ascii wide
        $ns4 = "xClient.Core.Packets.ServerPackets" ascii wide
        $ns5 = "xClient.Core.Packets.ClientPackets" ascii wide
        $ns6 = "xClient.Core.NetSerializer" ascii wide
        $ns7 = "xClient.Core.Registry" ascii wide
        $ns8 = "xClient.Core.Compression" ascii wide
        $msg1 = "DoShellExecute" ascii wide
        $msg2 = "DoStartupItemAdd" ascii wide
        $msg3 = "GetPasswords" ascii wide
        $msg4 = "GetSystemInfo" ascii wide
        $msg5 = "DoClientUpdate" ascii wide
        $lib1 = "AForge.Video.DirectShow" ascii wide
        $lib2 = "MouseKeyHook" ascii wide
        $ver1 = "Client.exe" wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 500KB and
        4 of ($ns*) and
        2 of ($msg*) and
        1 of ($lib*) and
        $ver1
}

Sigma rule

title: Quasar/xRAT xClient.Core Variant Execution
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: 'Client.exe'
        - OriginalFileName: 'Client.exe'
    selection_pe:
        - Product: 'Client'
        - InternalName: 'Client.exe'
    selection_dll_load:
        - ImageLoaded|contains:
            - 'AForge.Video.DirectShow'
            - 'MouseKeyHook'
    selection_network:
        Initiated: true
        DestinationPort:
            - 4782
            - 4783
            - 4784
            - 4785
    condition: 1 of selection_*
falsepositives:
    - Legitimate Quasar/xRAT remote administration tool use (rare in enterprise; correlate with approved software inventory)
level: high

IOC list

Type Value Notes
SHA256 1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd This sample
File name Unknown (triage filename=file) Original distribution filename not recovered
Original filename Client.exe Version-info field
Internal name Client.exe Version-info field
Assembly version 1.3.0.0 .NET metadata
Library AForge.Video.DirectShow Webcam capture
Library MouseKeyHook (namespace xClient.Core.MouseKeyHook) Global keyboard/mouse hooks
Library xClient.Core.NetSerializer Custom binary TCP serialization
Registry keys HKLM\Software\Microsoft\Windows\CurrentVersion\Run Startup persistence (generic)
Registry keys HKCU\Software\Microsoft\Windows\CurrentVersion\Run Startup persistence (generic)
Scheduled task Created via schtasks capa detection; generic pattern

Behavioral fingerprint

This binary is an unobfuscated .NET Framework 4.0 Client Profile PE32 executable with the internal name Client.exe and version 1.3.0.0. On execution it will load xClient.Core.MouseKeyHook for global keyboard capture, initialise the xClient.Core.NetSerializer TCP transport layer, and open outbound TCP connections to an operator-configured C2 server. It enumerates the local system (processes, drives, registry, network interfaces, geo-location), logs keystrokes, captures screenshots and webcam frames via AForge.Video.DirectShow, and supports remote shell execution, file-manager operations, reverse proxy tunneling, and browser credential recovery. Persistence is established via registry Run keys or scheduled tasks. No sandbox evasion, no anti-debug, and no packing is present — a superficially rebranded stock open-source RAT build.

Detection Signatures

capa → MITRE ATT&CK mapping (static-only, no runtime confirmation from CAPE):

capa capability ATT&CK Technique
gather chrome based browser login information T1555.003
log keystrokes via polling T1056.001
reference WMI statements / access WMI data T1047
schedule task via schtasks T1053.005
encode/decode data using Base64 T1140 / T1027
encrypt data using DPAPI T1553.005
create TCP socket / send data / receive data — (generic communication)
query or enumerate registry key/value T1012
create process in .NET T1129
set registry value T1112
enumerate processes T1057
get OS version / get hostname / get MAC address T1082
get geographical location T1614
bypass Mark of the Web T1553.005

References

  • Open-source project: https://github.com/quasar/Quasar (MaxXor)
  • Historical predecessor: xRAT / xClient codebase (namespaces preserved in this variant)
  • Artifact ID: 30f3a412-a744-421e-8059-829970a3e2bf
  • Source: OpenCTI → MalwareBazaar (mislabelled 9d2ca3)
  • Family page: quasar

Provenance

  • This report synthesized from static analysis outputs in raw/analyses/1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd/:
    • file.txt, pefile.txt, exiftool.json, rabin2-info.txt — build metadata and version info
    • strings.txt — unobfuscated .NET namespace and message-type enumeration (2,539 lines)
    • capa.txt — capability detection and ATT&CK mapping (static scope)
    • binwalk.txt — PNG icon in .rsrc at offset 0x17F81
    • floss.txt — command-line invocation failure; no decoded strings needed
    • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • radare2 analysis: opened with mcp_radare2_open_file, CIL architecture confirmed, 3,072 functions analysed at level 2
  • Tools: file v5.44, pefile 2023.2.7, ExifTool 12.76, radare2 5.9.2, capa v8.0.1, flare-floss (failed invocation), binwalk 2.3.2